> Markdown version of [/jobs/ext/1422410-security-engineer-cloud-security](https://www.wearedevelopers.com/jobs/ext/1422410-security-engineer-cloud-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Cloud Security - **Company:** Saronic Technologies - **Location:** Austin, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Identity and Access Management, Key Management, Software Vulnerability Management, Policy as Code, Amazon Virtual Private Cloud (VPC), Terraform, Devsecops - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bc753cad4f400c51 ## About the Role * 3+ years of hands-on cloud security, infrastructure security, or DevSecOps experience, or an equivalent combination of experience and demonstrated ability * Depth in AWS security services and architecture (IAM, Organizations/SCPs, CloudTrail, Config, GuardDuty, Security Hub, KMS, VPC) * Strong infrastructure-as-code (Terraform) and policy-as-code experience * Hands-on cloud vulnerability management and CSPM tooling (e.g., Prowler), with a track record of driving cloud findings to remediation * A track record of building guardrails or patterns that other teams adopted without friction * Proficiency in scripting for security automation * Ability to obtain and maintain a U.S. security clearance, * Prolonged periods of sitting at a desk and working on a computer * Occasional standing and walking within the office * Manual dexterity to operate a computer keyboard, mouse, and other office equipment * Visual acuity to read screens, documents, and reports * Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies * Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages), * Experience in AWS GovCloud, FedRAMP, or IL4/IL5 environments * Azure and on-prem security experience a plus * Multi-account landing-zone and organizational security design * CSPM with automated remediation at scale * Container or Kubernetes security * IAM attack-path analysis and outcome-based metrics * Familiarity with NIST SP 800-171/800-53 * Experience in defense, aerospace, robotics, or other high-assurance environments ## Description * Posture & Compliance: Own continuous cloud security posture management (CSPM) across all cloud accounts, detect misconfigurations and drift, and drive remediation with the teams that own the resources. Map technical controls to both government and commercial frameworks (CMMC, NIST SP 800-171, FedRAMP/IL baselines) and keep controls evidence current and audit-ready. * Cloud Vulnerability Management: Run cloud vulnerability management at scale, find issues, prioritize them by real attack path and exposure rather than raw CVSS, and drive remediation to closure. Use tooling such as Prowler and a CNAPP, and automate remediation wherever possible. * Guardrails & Secure-by-Default: Build reusable Terraform modules, Service Control Policies, permission boundaries, and policy-as-code that make the secure path the easy path, so whole classes of misconfiguration disappear before they reach production. Replace manual security gates with automated, self-service guardrails. * Identity, Secrets & Data Protection: Design least-privilege IAM across accounts and workloads, hunt privilege-escalation and cross-account trust paths, govern secrets management, and standardize encryption and key-management patterns. * Detection, Response & SOC Support: Build and tune cloud-native detections (CloudTrail, GuardDuty, Config, Security Hub) and automated remediation, and support the Security Operations team as they investigate, triage, and remediate cloud-related cases across our infrastructure, including credential compromise, exposed resources, and data exfiltration, reconstructing activity from logs and automating containment. Feed every incident back into new guardrails and detections. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)